Description
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.
Published: 2026-08-13
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unsafe deserialization flaw in the sblim-sfcb provider‑manager’s inter‑process communication parsing. When a specially crafted operation header is received, an out‑of‑bounds memory access occurs, terminating the provider‑manager process. The crash leads to a denial of service and may allow limited unintended disclosure of sensitive information. The weakness is identified as CWE‑125.

Affected Systems

The flaw affects Red Hat Enterprise Linux versions 6, 7, 8, 9 and 10.

Risk and Exploitability

The CVSS score is 6.6, reflecting a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The exploit requires local access; an attacker must be able to send a crafted IPC message to the provider‑manager. Successful exploitation will cause the service to stop, disrupting any processes that rely on sblim‑sfcb, but does not provide broader system compromise.

Generated by OpenCVE AI on August 13, 2026 at 13:24 UTC.

Remediation

Vendor Workaround

To mitigate this issue, restrict access to the local connect socket used by `sblim-sfcb` to prevent untrusted local users from obtaining the internal provider-manager descriptor. Deployments where only trusted users can reach this socket will have materially reduced exposure. Consult your system's documentation for appropriate methods to secure local IPC channels and socket permissions for the `sblim-sfcb` service. A restart of the `sfcbd` service may be required for changes to take effect, which could temporarily disrupt services relying on `sblim-sfcb`.


OpenCVE Recommended Actions

  • Restrict the local connect socket used by sblim‑sfcb so that only trusted users can write to it, using file permissions or ACLs.
  • Reboot or restart the sfcbd service after changing socket permissions to ensure the new restrictions take effect, while noting that this may temporarily disrupt services that depend on sblim‑sfcb.
  • Monitor the IPC channel for unusual activity and ensure no untrusted users have access to the socket.
  • When a vendor patch or update that fixes the unsafe deserialization bug becomes available, apply it promptly.

Generated by OpenCVE AI on August 13, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.
Title Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-13T15:10:32.658Z

Reserved: 2026-08-13T11:01:55.535Z

Link: CVE-2026-73583

cve-icon Vulnrichment

Updated: 2026-08-13T15:10:19.664Z

cve-icon NVD

Status : Received

Published: 2026-08-13T13:19:18.497

Modified: 2026-08-13T16:19:07.103

Link: CVE-2026-73583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:30:17Z

Weaknesses